SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

SonicWall Sounds Alarm as Threat Actors Exploit Critical Flaws in SMA1000 Appliances

Security experts are sounding the alarm after SonicWall warned that threat actors have been exploiting two critical vulnerabilities in its SMA1000 appliances. The company has urged customers to install newly released security updates immediately to prevent further attacks.

The vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, allow attackers to bypass security measures and gain unauthorized access to the affected systems. CVE-2026-15409 is a server-side request forgery (SSRF) flaw that can be exploited by remote, unauthenticated attackers to force the appliance to make requests to unintended locations. Meanwhile, CVE-2026-15410 is a post-authentication code injection vulnerability that can allow authenticated administrators to execute arbitrary operating system commands.

SonicWall has confirmed that both vulnerabilities are being actively exploited in zero-day attacks, and the company’s PSIRT team has investigated multiple incidents where these flaws were used to gain unauthorized access. The company has assigned an overall CVSS score of 10.0 to the advisory, indicating a critical severity rating.

The affected SMA1000 models include the 6210, 7210, and 8200v running platform-hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800. Fixes are available in platform-hotfix versions 12.4.3-03453 and 12.5.0-02835, and later releases.

It’s essential to note that these vulnerabilities do not impact SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line. However, administrators should be aware of the indicators of compromise (IOCs) provided by SonicWall to determine if their appliance has been compromised. These IOCs include suspicious requests in log files and configuration files.

To mitigate these vulnerabilities, SonicWall strongly recommends upgrading to the latest hotfix release and performing an analysis to determine if any of the above IOCs are present. If a device is found to be compromised, administrators should re-image physical appliances or redeploy virtual appliances, change all user and administrator passwords, and reset TOTP tokens.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming they are being actively exploited in attacks. Federal agencies have until July 17, 2026, to secure affected systems under Binding Operational Directive (BOD) 26-04 or discontinue use of the product if mitigations cannot be applied.

In light of these findings, it’s crucial for security teams to prioritize patching and testing their systems regularly to prevent similar attacks in the future. As SonicWall notes, there are no workarounds or mitigations for these flaws other than installing the hotfixes. By staying vigilant and taking proactive measures, organizations can minimize the risk of falling victim to these types of attacks.

To protect your organization’s security posture, we recommend regularly testing every layer of your environment with breach and attack simulation tools. This will help identify vulnerabilities before attackers do and ensure that your SIEM and EDR rules are effective in detecting threats.


Source: Bleeping Computer — 2026-07-14